Component · for humans & their agents
Knowledge-Graph Merge
verified · first-partyactively maintained$0 during beta (was $39)
Two extractors disagree about the same entity. The naive merge is a spread, the last writer wins, and the only evidence anything was lost is that the answer changed.
by saltyhash · Code Recycle admin
Every claim on this page is refundable if it is untrue — refund policy.
Verified: 25 tests · 10/10 mutations caught
Every system that extracts facts from documents eventually writes the same entity twice — two emails, two PDFs, two extractors, a human typing over the top.
The failure it prevents
Every system that extracts facts from documents eventually writes the same entity twice — two emails, two PDFs, two extractors, a human typing over the top.
The naive merge is `{...existing, ...incoming}`. The last writer wins, so a low-confidence guess pulled from a page-three footer silently overwrites a fact a person entered by hand. Nothing errors. Nothing logs. The only trace is that the answer is different now.
The rules it enforces
1. Aliases and source references are append-only. Evidence accumulates; a merge never trades it away. 2. High confidence is never overwritten by low. 3. Human-entered data outranks any extractor — and `createdBy` is immutable, because a later automated write that relabels the record would switch the rule off for exactly the rows it exists for. 4. A real disagreement is recorded, not resolved. Two high-confidence sources that differ keep the existing value and append a conflict record for a human. 5. Confidence is monotonically non-decreasing. One low-confidence touch cannot downgrade a well-attested node out from under everything that thresholds on it. 6. Visibility narrows, never widens. The most restrictive wins — the one rule here with a disclosure consequence, so it fails closed. 7. A pinned node still accumulates provenance. Declaring a node canonical freezes its name and properties, not the evidence trail that lets anyone check it.
Your ontology, not ours
Node and edge type vocabularies are plain strings. None of the merge rules read them — a conflict between two confidence values resolves the same whether the node is a person or a parcel — so you narrow them in your own code instead of adopting someone else's nouns.
What it does not do
It does not decide that two different ids are the same entity; resolution is a separate problem, and it throws on an id or type mismatch rather than welding two entities together. And it does not resolve conflicts — it records them. A merge that adjudicates disputed facts on its own is the thing this replaces.
Verified
25 tests, and 10 deliberate defects applied to the real source — all 10 caught, including last-write-wins, widening visibility, a rewritten `createdBy`, and conflicts computed and then dropped on the floor. The set ships in the source.
Delivery
Source delivered as a private repository invite within 24 hours of purchase. Single-product commercial license: use and modify in any number of products; no redistribution or resale of the source.
Interface
What you call, and what comes back. Types and signatures only — the implementation ships with the source.
export function mergeGraphNodes( existing: GraphNodeShape, incoming: GraphNodeWrite, now: Date = new Date(), opts?:;
export function mergeGraphEdges( existing: GraphEdgeShape, incoming: GraphEdgeWrite, now: Date = new Date(), ): GraphEdgeShape;01Capabilities
Does
- + Audit logs
- + Entity resolution
- + Duplicate and sybil detection
Doesn’t
- No exclusions declared
02Requirements & stack
Depends on
No declared dependencies
Credentials needed
None declared
Stack
03Community
No endorsements yetNo verified confirmations yet — be the first.
Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.
Sign in to confirm — weight comes from verified usage, not vote count.
Issues 1
Open an issue0 open · 0 answered · 0 fixed · 1 said it worked
- closedWorked for me — 25/25 vitest on Node 26.0.0, macOS 26.4Worked for me
04Trust Passport
Full passport →0/0 automated components pass. An automated score is never a security guarantee.
- publisher identity Publisher status verified; 1 verification(s) on file
- malicious pattern scan No known malicious-behavior patterns across 8 source file(s) plus listing text
- capability contract All 0 observed capability reference(s) match the declared manifest
- agent safety scan No injection patterns in agent-readable content
- provenance No release signature or provenance attestation
- behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.
Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.
05Versions
Full history →| Version | Channel | Released | Notes |
|---|---|---|---|
| 1.0.0 | stable | Aug 10, 2026 | First public release. |